Malware.View on attack.mitre.org
Dtrack is spyware that was discovered in 2019 and has been used against Indian financial institutions, research facilities, and the Kudankulam Nuclear Power Plant. Dtrack shares similarities with the DarkSeoul campaign, which was attributed to Lazarus Group.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Dtrack can collect a variety of information from victim machines. |
| T1012 Query Registry |
Dtrack can collect the RegisteredOwner, RegisteredOrganization, and InstallDate registry values. |
| T1016 System Network Configuration Discovery |
Dtrack can collect the host's IP addresses using the |
| T1027.009 Embedded Payloads |
Dtrack has used a dropper that embeds an encrypted payload as extra data. |
| T1036.005 Match Legitimate Resource Name or Location |
One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla. |
| T1049 System Network Connections Discovery |
Dtrack can collect network and active connection information. |
| T1055.012 Process Hollowing |
Dtrack has used process hollowing shellcode to target a predefined list of processes from |
| T1056.001 Keylogging |
Dtrack’s dropper contains a keylogging executable. |
| T1057 Process Discovery |
Dtrack’s dropper can list all running processes. |
| T1059.003 Windows Command Shell |
Dtrack has used |
| T1070.004 File Deletion |
Dtrack can remove its persistence and delete itself. |
| T1074.001 Local Data Staging |
Dtrack can save collected data to disk, different file formats, and network shares. |
| T1078 Valid Accounts |
Dtrack used hard-coded credentials to gain access to a network share. |
| T1082 System Information Discovery |
Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier. |
| T1083 File and Directory Discovery |
Dtrack can list files on available disk volumes. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.